As the CES is cloud deployment. The Public NAT IPs of your onprem applications needs to be allowed at CES to relay the emails.
Usually, if the recipient is internal domain user, then the application directly sends to your Exchange/O365 server and if the recipient is external then the application sends to CES to deliver to the external email server. Thanks.